|
VMware Security Update Fixes Multiple Code Execution Vulnerabilities |
|
|
|
Source: FrSIRT - Posted by Bill Keys
|
Multiple vulnerabilities have been identified in various VMware products, which could be exploited by local or remote attackers to bypass security restrictions, cause a denial of service or compromise a vulnerable system.The first issue is caused by an input validation error in the "HGFS.sys" driver, which could allow local attackers to execute arbitrary code on the guest system.
The second vulnerability is caused by an untrusted library path error in "vmware-authd", which could be exploited by local unprivileged attackers to execute arbitrary code on the Linux host system.
Have you heard about the news that vulnerabilities have been found in some of VMware's software. This started to make me think what is the state of virtualization security? Do you think it's just as secure as a host installed on physical hardware?
Read this full article at FrSIRT
http://www.frsirt.com/english/advisories/2008/1744 |